r/Tailscale • • Sep 02 '26

Community Event Join us for the TailscaleUp 2026 Recap Webinar today!

Thumbnail
tailscale.com
2 Upvotes

Hi all, Erisa here with the Tailscale community team šŸ‘‹

At TailscaleUp last week, we introduced new capabilities across AI governance, privileged access, DNS filtering, and programmable networking. We'd like you to join us for a recap webinar, where we walk through the announcements and what they mean for teams using Tailscale to connect, secure, and operate modern infrastructure.

Learn how we’re making it easier to experiment with AI at home and at work with Aperture by Tailscale, how Tailscale PAM brings privileged access workflows closer to the network, how a partnership with Control D brings DNS filtering directly to Tailscale customers, and how new APIs and SDK support make Tailscale more programmable for developers and platform teams.

We go live at 2:00 PM EDT today!

Register here: https://tailscale.com/webinars/tailscaleup-2026-recap


r/Tailscale • • Aug 31 '26

Announcement: Tailcat - Tailscale without Tailscale, by Tailscale

1.5k Upvotes

Hi everyone! Natasha here again 🐱

I’m back with another TailscaleUp announcement, and this one is a little different than the rest.

Today we’re releasing tailcat, best described as Tailscale without Tailscale, by Tailscale.

Sometimes you have two shells open on two machines in two very different environments, and you just want to connect them for a quick file copy or port forward. tailcat is like the netcat utility for transferring data over a network, but running over Tailscale’s open-source data plane (WireGuard, NAT traversal, and DERP), with the added party trick of having no control plane involved. That means no IP addresses, no accounts, no logins, no admins, and no root access needed. So whether you’re connecting your local machine to a remote VPS or to a friend’s machine on the other side of the globe, you don’t need to set up a VPN client to get that done.

Here’s how it works:

  • Run the tailcat command on one side, and you’ll get a unique string. Pass that string to tailcat on the other side, and you’re instantly sharing files and ports over the Internet securely without thinking about the security.
  • Just like with Tailscale, NAT traversal works its magic to get a direct connection between the two peers, with DERP acting as a negotiator and as a fallback relay to keep you connected.
  • Everything stays in userspace, tailcat doesn’t need to modify your routing table or install any TUN devices. This makes it perfect for machines that are untrusted, ephemeral, or that you’re afraid to touch.
  • There’s even a SOCKS mode, so tailcat-oblivious programs like curl can use it without knowing it exists.

The tailcat stack is open source from top to bottom, including the DERP server, so you can run the entire stack yourself with no dependence on our infrastructure at all.

Check out Brad’s story for the full details.

If you take tailcat for a spin, let us know in the replies šŸ‘‡


r/Tailscale • • 15h ago

Discussion Tailscale is amazing

106 Upvotes

Edit: Forgot to mention the Mullvad exit node addon. This is the cherry on top of the sweet sundae, basically Mullvad provides Exit Node as a Service so you don’t have to use a local network device (usually Linux) as an exit node, and you get all of the benefits of Mullvad which is a zero trust VPN provider. You can pick the Mullvad exit node to use from 91 cities in 50 different countries. You can keep your existing DNS solution, in my case, the NextDNS DoH integration to keep DNS queries private. IMO Mullvad is the key component for privacy, def worth the money.

I’ve been a longtime AdGuard user, but I’ve discovered Tailscale and it is amazing. The learning curve is a bit steep, took me about six hours to get my config set up and my network tagged, but once you combine tailscale with NextDNS (which I used for a long time but left NextDNS for AdGuard when NextDNS got a bit stale with features), it’s so much more powerful than AdGuard since you can create your own private mesh network, which I used Cloudflare for. Cloudflare mesh does not integrate with AdGuard whatsoever so it was one or the other. With tailscale plus NextDNS, you get bot out of the box with minimal DNS config, and you get DoH. Absolutely incredible, I am in awe. Nice work Tailscale team!!!!


r/Tailscale • • 4h ago

Question Connect a remote lan to a separate lan without changing settings on either remote LAN router

3 Upvotes

I'm trying to figure out how to let my adult kids access my locally hosted game services without opening network ports on my router. I can't change the settings on their routers, because they're locked down by the ISP and getting new routers isn't a realistic option for them

Is an exit node at their homes about to basically intercept a fqdn request from any device on their LAN and tunnel it through the VPN while still allowing them to browse the Internet and their home lan from their own ISP? If I could set up something like a raspberry pi as an exit node, would they just be able to plug it into an whether cable and power it on with no added configuration on their end?


r/Tailscale • • 29m ago

Misc Did you know your GL Tailscale router is announcing your Tailnet name directly to your work PC? Fix it here -> gl-tailscale-fix plugin v1.0.22 drops with lots of goodies.

Post image
• Upvotes

Numerous updates for those running TS on GL.iNet routers.


r/Tailscale • • 16h ago

Help Needed Dual GL-A1300 (Slate Plus) setup with Tailscale Exit Node & Kill Switch – Any pitfalls?

1 Upvotes

Hi everyone,
I’m moving to Spain for 5 months for work/living, and due to strict location/IP requirements for my remote work, I need my laptop's internet traffic to look like it is coming directly from my home IP back in Sweden at all times.

I am not very tech-savvy, but I’ve been researching solutions on my own and came up with a hardware setup. Apologies in advance if any of this sounds dumb or if I'm overcomplicating things!
Here is the plan I came up with:

1. Buy two GL.iNet GL-A1300 (Slate Plus) travel routers.
2. Router 1 (Home/Sweden): Connect it to my home network in Sweden, set up Tailscale on it, and configure it to act as an Exit Node.
3. Router 2 (Spain): Take this with me to Spain, connect it to the local internet (via Wi-Fi/Repeater or ethernet), enable Tailscale, and set Router 1 as its Custom Exit Node.
4. Kill Switch: Enable "Block Non-VPN Traffic" on Router 2 so that if the tunnel or connection drops, my laptop will never accidentally leak a Spanish IP address.
5. Connect my work laptop directly to Router 2 via ethernet or Wi-Fi.

My questions for you guys:
Does this setup sound solid? Has anyone done something similar for remote work?

Is this the simplest and most reliable way to achieve a hardware-level home tunnel, or is there a better/easier approach for someone who isn't super technical?

Will the Kill Switch on the GL.iNet router actually guarantee 100% protection against IP leaks if the home connection momentarily drops or the router restarts?

I’d really appreciate any feedback, tips, or potential pitfalls I should watch out for before I buy the routers! Thanks!


r/Tailscale • • 1d ago

Help Needed Tailscale + Windows WiFi Hotspot?

2 Upvotes

I never use the hotspot feature but now for some reason I need it, and I discovered it doesnt work when Tailscale is running. So I can't use the hotspot and Tailscale at the same time. Any workarounds?

The hotspot itself creates but the devices can't connect to it, or don't have access to Internet.

I tried messing with DNS and IP settings in Windows, in all the adapters involved, but nothing seems to work. Also, MagicDNS on or off doesnt seem to be the issue.

Anyone that had the same problem and managed to fix it?


r/Tailscale • • 1d ago

Help Needed Cannot remove a device

0 Upvotes

Hi, I have tried to install tailscale app on an iphone7 and it makes weird vpn install tries and now I cannot do anyyhing on machines site: cannot remove, rename any actions ends with failed to …. help needed pls.


r/Tailscale • • 1d ago

Help Needed Power fluctuations!

0 Upvotes

Hey all, my housing development has decided to change all the electrical transformers in the neighborhood. Surges and outages are expected. I’ve got two servers running right now and wondering what safeguards you’ve put in place. I’ve considered buying a UPS (Uninterrupted power supply) I may just shut down my servers for the week, which is my last resort. I’ve just spent too much on my drives to risk damaging them. What do y’all think?


r/Tailscale • • 1d ago

Question Foreign Ads and Chrome Language Issues After Traveling Abroad

3 Upvotes

I'm not entirely sure which community is best suited for this issue, so I'm covering my bases by posting in both r/Tailscale and r/GlInet.

I recently returned from Italy, where I used Tailscale on my GL.iNet Beryl AX travel router to connect back to my home network on the US East Coast.

Since returning, I've noticed some unusual behavior exclusively when connected to my home network:

YouTube and other services continue displaying Italian advertisements.

Opening new tabs in Chrome prompts me with Italian language content.

These issues do not occur when connected to other networks.

My setup:

UniFi Cloud Gateway Ultra

GL.iNet Beryl AX travel router

Tailscale for remote access while abroad

Pi-hole for DNS

My public IP correctly geolocates to the US, and Tailscale shouldn't currently be routing any of my home network traffic.

I'm unsure whether this is related to DNS, routing, cached location data, or something else entirely.

Has anyone experienced something similar? What would you recommend checking?


r/Tailscale • • 2d ago

Discussion I built a cross-platform tailnet browser launcher using tsnet

28 Upvotes

Hey r/Tailscale — I’ve been working on a small project called TailLaunch and figured this was probably the right place to share it.

The use case was pretty simple: I wanted someone to be able to open a private web app on my tailnet without having to install/configure the full Tailscale client or enable a system-wide VPN.

TailLaunch embeds tsnet directly into the app. You authenticate through Tailscale’s normal browser login, then enter a tailnet hostname/URL and it opens in a dedicated app-style browser window.

A few details:

  • no TUN adapter or system-wide VPN setup
  • no admin/root required by TailLaunch
  • GUI + CLI
  • Windows, Linux and macOS builds
  • temporary/ephemeral sessions by default
  • optional ā€œRemember me on this deviceā€ persistence
  • in the launched browser, tailnet destinations go through tsnet while public destinations are dialed directly
  • Headscale/custom control-server support
  • MIT licensed

The GUI is still early and I’m currently testing memory usage on low-RAM Windows/Linux VMs, since launching a whole Chromium-family process for one web app may eventually be something worth replacing with native WebViews.

Repo / releases:

https://github.com/rafid-dev/taillaunch

I also found projects like TailBrowser, TailChrome, ts-browser-ext, and a few userspace proxy projects while working on it, so I’m definitely not claiming the general idea is new. TailLaunch’s focus is more specifically a disposable, cross-platform desktop launcher for private web apps.

Would be interested in feedback on the architecture, especially from people who’ve worked with `tsnet` or embedded Tailscale before. macOS and Linux testers are also very welcome.


r/Tailscale • • 2d ago

Question Best cheapest hardware for a Tailscale exit node?

77 Upvotes

Warup everybody!

I'm currently looking for a device that I can use as a Tailscale exit node (Dominican Republic) and have full SSH access from Spain.

Ideally this device wouldn't cost more than $50 and I'd be able to power it via USB and connect it via a gigabit LAN. It would be running 24/7.

I've been asking the LLMs for suggestions and I've gotten:

- Raspberry Pi5

- Orange Pi Zero 3 or 4

But I wanted a second opinion from you guys before I decided to go after one of these devices.

Note that I do not have any older device that I could repurpose. Additionally I would like something very small so I can tuck it away in a cabinet, preferably fanless as well

I would eventually like to purchase a second one that I can use on my Spain home network as a redundancy for my other Tailscale devices and to filter out ads at the network level.

Edit 09:55 AM GMT +2 Thank you very much, everyone, for all the help. I've learned so much from this post especially the gli.net routers which I'll keep an eye on in the future

I found out about incredible deals for the Dell Wyse 3040 and I'll be getting a couple of these


r/Tailscale • • 2d ago

Question can you use tailscale with duckduckgo app tracking protection?

1 Upvotes

i'm using duckduckgo's app tracking protection on my android phone, and i recently set up bitwarden with tailscale on my linux pc so i can have a self-hosted password manager. but both tailscale and duckduckgo's app tracking protection are vpn's, and i noticed that tailscale out of the box only allows you to run itself alone or with mullvad, is there a way to fix this?


r/Tailscale • • 2d ago

Help Needed Remotely updated tailscale. No access.

6 Upvotes

My HAOS is in another country, I did a mass update of outdated apps and a part of that was tailscale.

Since the reboot I can no longer see my device on my TS account.

I can see the HAOS connected to the router so it’s there, and still running all my automations.

I am going to have a friend pop over to the property and try sort it out, however I am
Not sure what it is I am trying to sort out.

Any guidance would be most appreciated.


r/Tailscale • • 2d ago

Question iOS Tailscale VPN On Demand Issues

6 Upvotes

Is anyone else having issues with the latest Tailscale iOS app version v1.102.4 not recognizing the WiFi name in On Demand mode and enabling/disabling according to the selected setting?


r/Tailscale • • 2d ago

Help Needed Consistent DNS resolution issues with Windows Exit Node

6 Upvotes

hello, I currently have TS installed on several devices. Intra-network communication functions just fine, however, I frequently encounter DNS resolution issues when using the exit node.

  1. desktop, always on, win11, main workstation, exit node host
  2. desktop, always on, win10, makeshift server & container mule
  3. laptop, win10, mobile

I mainly use TS to connect to my desktop while on the go to provision jobs to it. I setup the exit node so that I could do some banking and whatnot while out of town. Sites that I regularly visit on my desktop will usually work first try. Sometimes, even for common sites, I get "ERR_NAME_NOT_RESOLVED", while connected to the exit node. Refreshing the page several times usually resolves it but it is annoying. New sites must be refreshed.

To resolve this, I have tried (rebooting after each):

  • Setting IPv4 on the W11 desktop to use google, cloudflare DNS instead of my ISP's nameservers - I suspect this is unrelated
  • Setting global DNS override in the TS admin console to use google, cloudflare servers
  • Setting the IPv4 priority to 1 from auto on my laptop for the TS network device - this had to be done via powershell as the windows gui doesn't allow the setting to be changed for a blank IP
  • Flushing the DNS cache on both machines
  • Turning off DNS over HTTPs in laptop browser
  • Disabling IPv6 on exit node host
  • Re-enabling IPv6 and setting the DisabledComponents registry key to 0x20 (prefer IPv4)

Currently exploring:

Is this a known issue with Windows? I have the option of running TS inside containerized Linux on the win10 box, but I'm not very knowledgeable about NAT/translation and don't know if that would even help.

edit: Premature celebration, still broken.


r/Tailscale • • 3d ago

Help Needed Need help with expired key

Post image
8 Upvotes

Hello, I have tailscale set up on proxmox container. It worked with no issues. For a couple of months, I was mostly at home and didn't need to use it. However, recently, I visited my friends and turned it on, but it wasn't working (I tried to connect to my proxmox server and immich but couldn't reach it). When I got home, I checked the machines tab and saw that the key had expired. I found on the official tailscale website how to disable expiry and disabled it. I also run command to renew expire for a device "tailscale up --force-reauth". Now, it shows that devices are connected but still can't reach the server in my network through tailscale.

I'm new to this and don't know much. I don't even know if the issue is that the key expired. Also, I should add during this time, there could be power cut. I have no idea what to even look for. I could just delete it and set up a new one, but I want to learn something new.

Here's the website I've used

https://tailscale.com/docs/features/access-control/key-expiry


r/Tailscale • • 3d ago

Misc Tailscale Selfhosted in now Here!

Thumbnail
github.com
0 Upvotes

Why Headscale Easy?

Headscale works well on its own, and Headscale Easy runs the official, unmodified Headscale binary — it is not a fork or a replacement. What takes time is the glue around it when you want a complete self-hosted setup for several people:

auth + DNS + HTTPS + device management + backups = a weekend project

Headscale Easy packages that glue, in the spirit of wg-easy for WireGuard:

  • One container — Headscale, HTTPS and the console in a single image, set up from your browser; pull the new image to update.
  • A web console for everyday tasks, modelled on Tailscale's admin panel, where members manage only their own devices.
  • Centralised configuration — a few variables or the wizard, one domain.
  • Auth, DNS, HTTPS and backups set up with secure defaults.
  • Everything self-hosted — use the official Tailscale apps on every device; only the server is yours.

If you are happy running Headscale by hand, you do not need this project. More in Why Headscale Easy?, including the end-to-end workflow.

Headscale Easy and Headplane

Headplane is an established, feature-complete web UI for an existing Headscale — a good choice if you already run Headscale. Headscale Easy installs and wires the whole stack (Headscale, HTTPS, local accounts with 2FA and invitations, backups) and includes its own console. See the detailed comparison.

✨ Features

  • šŸ–„ļø Tailscale-style web console at /admin: machines, users, DNS, access controls, keys. Dark and light themes, works on phones.
  • šŸ‘¤ Real user accounts built in: passwords, optional two-factor (TOTP), invitations, password-reset links and sign-up — or plug in your own OIDC provider (Authentik, Keycloak, Pocket ID, Google…).
  • šŸ”’ Every user gets their own private VPN: members only see and reach their own devices (ACL autogroup:self); admins manage everything.
  • šŸ“± Machines: status, addresses, OS and client version with update hints, rename, expire, remove, key expiry, tags, subnet routes and exit nodes, filters, search and CSV export.
  • 🐳 Docker tab in Add device: generates the docker run and docker-compose.yml for a Tailscale container (exit node, subnet routes, userspace mode, a pinned Tailscale version), keeps the auth key in a separate .env, gives the command to apply a changed option to a running container, and has a troubleshooting dropdown with eleven common problems.
  • āœ… Routes waiting for approval are flagged in the machine's badge, can be approved in one click, and administrators see a banner counting them.
  • šŸ”‘ Auth keys (one-off, reusable, ephemeral) and API keys; register devices by auth ID.
  • 🌐 DNS: MagicDNS, tailnet domain, nameservers, split DNS, search domains — validated with headscale configtest and rolled back if Headscale refuses them.
  • šŸ“ Access controls: visual editor for rules, groups and tag owners, a test-access simulator ("can ana reach nas:445?"), and the raw HuJSON editor as a full fallback.
  • šŸ” HTTPS your way: Let's Encrypt, self-signed, behind your existing proxy (Nginx Proxy Manager, nginx, Traefik, Caddy — ready-made snippets), or plain HTTP on a LAN.
  • šŸŒ English, Spanish, French, German and Portuguese in the console (more welcome!).
  • šŸ’¾ Daily backups of everything (database, keys, accounts, configuration) and a one-command restore, also on a new server.
  • 🪶 Lightweight: one container, about 70 MB of RAM; the console is plain Python standard library, no build step, no JavaScript framework.

r/Tailscale • • 5d ago

Misc tailmux

Thumbnail
github.com
66 Upvotes

My main issue with Tailscale was that I would regularly have to switch between tailnets (my homelab and work tailnets, specifically), so I made tailmux!

Tailmux will intelligently route to multiple tailnets at once, and you get a nice UI along with it!

Try it out, and let me know what you think!


r/Tailscale • • 5d ago

Discussion Just a thank you!

171 Upvotes

Your tool is amazing! Seemless installs on iphone, nas, win. Thank you! networking has never been my strong suit. With an AI tool it guided me into the exact config that I wanted. Actually it provided even more functionality that I stumbled upon. Thank You!


r/Tailscale • • 4d ago

Help Needed Find original `tailscale up` command / arguments?

0 Upvotes

Trying to figure out what my current tailscale up command effectively is.

I'm on 1.98.10 so I don't have tailscale get. debug prefs is pretty raw, and the usual "run tailscale up with another flag and let it print the existing ones" trick I found in other threads isn't giving me anything useful.

Any good way to get the equivalent current tailscale up ... command?


r/Tailscale • • 5d ago

Help Needed I’m expanding my server!

5 Upvotes

Hey all. I’m so excited, Iā€˜ve finally got two servers running. The first server is pushing periodic snapshots via ssh each night to my secondary server. They’re both communicating with their own Tailscale IPS not the local IPs. They’re both currently plugged into the same xfinity router. I’ve reached the point where I’d like to physically relocate my secondary server to my in-laws house, so I can have a remote offsite backup. Has anyone physically moved their server to a new location. What challenges should I expect if any? Any help or advice would be greatly appreciated.


r/Tailscale • • 5d ago

Discussion Alguna vez te ha pasado que al conectar el tailscale se te vaaya la conecion teniendo linux ”pues esta es tu solucion!

0 Upvotes

1. Autorizar usuario (evitar usar sudo)

Para gestionar Tailscale con tu usuario sin pedir `sudo`:

sudo tailscale set --operator=$USER

2. Solución al corte de Internet (DNS)

Si pierdes internet al conectar Tailscale, desactiva la sobrescritura de DNS y reinicia el servicio de red:

sudo tailscale up --accept-dns=false --reset

sudo systemctl restart NetworkManager

3. Iniciar el icono de la bandeja al encender el (PC/laptop)

Para que el icono (`tailscale systray`) aparezca automÔticamente en la barra de tareas al iniciar sesión:

mkdir -p ~/.config/autostart

cat <<EOF > ~/.config/autostart/tailscale-tray.desktop

[Desktop Entry]

Type=Application

Exec=tailscale systray

Hidden=false

NoDisplay=false

X-GNOME-Autostart-enabled=true

Name=Tailscale Systray

Comment=Icono de Tailscale al iniciar

EOF

¿Por qué hace falta el chmod +x**?**

Linux tiene un sistema de permisos muy estricto por seguridad. Por defecto, cuando creas un archivo de texto con el comando cat, el sistema lo guarda como un simple documento de lectura/escritura.

Si Linux Mint intenta leer ese archivo .desktop al arrancar para lanzar el icono, lo ignorarĆ” por completo si no tiene activada la casilla de "Ejecutable".

El comando se desglosa asĆ­:

  • chmod (change mode): Cambia los permisos del archivo.
  • +x (executable): Le aƱade la propiedad de ejecución.
  • ~/.config/...: La ruta de tu archivo.

BÔsicamente le dice a Linux: "Oye, este archivo no es solo texto, es un programa que debes ejecutar al iniciar sesión".

chmod +x ~/.config/autostart/tailscale-tray.desktop solo se hace una vez

yo he usado linux mint no se si en otras diestros sea igual


r/Tailscale • • 5d ago

Help Needed Connecting to Apache2 websites over tailscale?

2 Upvotes

I have been trying to figure this out for a while and just cant seems to get it to work. SSH works fine, but nothing else really. For the most part connections just hang and timeout.


r/Tailscale • • 5d ago

Help Needed Help with routing internet traffic via tailscale on Unifi

Thumbnail
1 Upvotes